Squid: request/response smuggling in http/1.1 and icap
Published Nov 3, 2023
9.3
CRITICALCVSS 3.1
EPSS 6.21%
Description
SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 6 | affected |
|
Configuration 1
- ≥ 2.6 · < 6.4
Configuration 2
- 8.0
- 9.0
- 8.6
- 8.8
- 9.0
- 9.2
- 8.0_aarch64
- 8.0_s390x
- 8.0_ppc64le
- 8.2
- 8.4
- 8.6
- 9.2
- 8.2
- 8.4
- 8.6
- 8.8
- 9.2
No data.
Red Hat Enterprise Linux 7 Extended Lifecycle Support
squid-7:3.5.20-17.el7_9.13
Fixed · RHSA-2024:11049
Red Hat Enterprise Linux 8
squid:4-8080020231030214932.63b34585
Fixed · RHSA-2023:6267
Red Hat Enterprise Linux 8
squid:4-8090020231030224841.a75119d5
Fixed · RHSA-2023:7213
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
squid:4-8010020231101141358.c27ad7f8
Fixed · RHSA-2023:6810
Red Hat Enterprise Linux 8.2 Advanced Update Support
squid:4-8020020231101135052.4cda2c84
Fixed · RHSA-2023:6803
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
squid:4-8020020231101135052.4cda2c84
Fixed · RHSA-2023:6803
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
squid:4-8020020231101135052.4cda2c84
Fixed · RHSA-2023:6803
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
squid:4-8040020231101101624.522a0ee4
Fixed · RHSA-2023:6804
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
squid:4-8040020231101101624.522a0ee4
Fixed · RHSA-2023:6804
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
squid:4-8040020231101101624.522a0ee4
Fixed · RHSA-2023:6804
Red Hat Enterprise Linux 8.6 Extended Update Support
squid:4-8060020231031165747.ad008a3a
Fixed · RHSA-2023:6801
Red Hat Enterprise Linux 9
squid-7:5.5-5.el9_2.1
Fixed · RHSA-2023:6266
Red Hat Enterprise Linux 9
squid-7:5.5-6.el9_3.1
Fixed · RHSA-2023:6748
Red Hat Enterprise Linux 9.0 Extended Update Support
squid-7:5.2-1.el9_0.3
Fixed · RHSA-2023:6268
Red Hat Enterprise Linux 6
squid
Will not fix
Red Hat Enterprise Linux 6
squid34
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | squid-7:3.5.20-17.el7_9.13 | Fixed | RHSA-2024:11049 |
| Red Hat Enterprise Linux 8 | squid:4-8080020231030214932.63b34585 | Fixed | RHSA-2023:6267 |
| Red Hat Enterprise Linux 8 | squid:4-8090020231030224841.a75119d5 | Fixed | RHSA-2023:7213 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | squid:4-8010020231101141358.c27ad7f8 | Fixed | RHSA-2023:6810 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | squid:4-8020020231101135052.4cda2c84 | Fixed | RHSA-2023:6803 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | squid:4-8020020231101135052.4cda2c84 | Fixed | RHSA-2023:6803 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | squid:4-8020020231101135052.4cda2c84 | Fixed | RHSA-2023:6803 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | squid:4-8040020231101101624.522a0ee4 | Fixed | RHSA-2023:6804 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | squid:4-8040020231101101624.522a0ee4 | Fixed | RHSA-2023:6804 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | squid:4-8040020231101101624.522a0ee4 | Fixed | RHSA-2023:6804 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | squid:4-8060020231031165747.ad008a3a | Fixed | RHSA-2023:6801 |
| Red Hat Enterprise Linux 9 | squid-7:5.5-5.el9_2.1 | Fixed | RHSA-2023:6266 |
| Red Hat Enterprise Linux 9 | squid-7:5.5-6.el9_3.1 | Fixed | RHSA-2023:6748 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | squid-7:5.2-1.el9_0.3 | Fixed | RHSA-2023:6268 |
| Red Hat Enterprise Linux 6 | squid | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This attack is limited to the HTTP/1.1 and ICAP protocols which support receiving Transfer-Encoding:chunked.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Dec 19, 2023 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (38 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.21% (0.06210) | 93.31th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.25% (0.05255) | 91.45th | v5 (v2026.06.15) |
| May 29, 2026 | 9.82% (0.09816) | 93.09th | v4 (v2025.03.14) |
| May 24, 2026 | 8.38% (0.08378) | 92.41th | v4 (v2025.03.14) |
| Dec 28, 2025 | 9.62% (0.09618) | 92.62th | v4 (v2025.03.14) |
| Dec 27, 2025 | 4.95% (0.04954) | 89.35th | v4 (v2025.03.14) |
| Nov 27, 2025 | 9.85% (0.09854) | 92.68th | v4 (v2025.03.14) |
| Nov 22, 2025 | 8.41% (0.08411) | 91.95th | v4 (v2025.03.14) |
| Nov 21, 2025 | 9.62% (0.09618) | 92.56th | v4 (v2025.03.14) |
| Nov 18, 2025 | 27.74% (0.27743) | 96.16th | v4 (v2025.03.14) |
| Oct 28, 2025 | 9.85% (0.09854) | 92.63th | v4 (v2025.03.14) |
| Oct 27, 2025 | 5.08% (0.05084) | 89.34th | v4 (v2025.03.14) |
| Oct 1, 2025 | 9.62% (0.09618) | 92.63th | v4 (v2025.03.14) |
| Jul 30, 2025 | 5.08% (0.05084) | 89.39th | v4 (v2025.03.14) |
| Jul 18, 2025 | 9.85% (0.09854) | 92.61th | v4 (v2025.03.14) |
| Jul 16, 2025 | 8.41% (0.08411) | 91.90th | v4 (v2025.03.14) |
| Jun 25, 2025 | 9.85% (0.09854) | 92.60th | v4 (v2025.03.14) |
| Jun 20, 2025 | 8.41% (0.08411) | 91.87th | v4 (v2025.03.14) |
| Apr 15, 2025 | 9.85% (0.09854) | 92.49th | v4 (v2025.03.14) |
| Mar 30, 2025 | 27.74% (0.27743) | 96.03th | v4 (v2025.03.14) |
| Mar 29, 2025 | 44.65% (0.44646) | 96.40th | v4 (v2025.03.14) |
| Mar 28, 2025 | 27.74% (0.27743) | 96.02th | v4 (v2025.03.14) |
| Mar 27, 2025 | 44.65% (0.44646) | 97.13th | v4 (v2025.03.14) |
| Mar 25, 2025 | 27.74% (0.27743) | 95.98th | v4 (v2025.03.14) |
| Mar 24, 2025 | 44.65% (0.44646) | 97.29th | v4 (v2025.03.14) |
| Mar 17, 2025 | 27.74% (0.27743) | 96.03th | v4 (v2025.03.14) |
| Dec 18, 2024 | 2.48% (0.02477) | 89.75th | v3 (v2023.03.01) |
| Dec 12, 2024 | 1.19% (0.01191) | 85.75th | v3 (v2023.03.01) |
| Nov 9, 2024 | 1.52% (0.01516) | 87.42th | v3 (v2023.03.01) |
| May 10, 2024 | 0.34% (0.00337) | 71.17th | v3 (v2023.03.01) |
| Mar 22, 2024 | 0.32% (0.00318) | 69.86th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.41% (0.00412) | 73.27th | v3 (v2023.03.01) |
| Jan 10, 2024 | 0.41% (0.00412) | 71.27th | v3 (v2023.03.01) |
| Dec 1, 2023 | 2.33% (0.02325) | 88.52th | v3 (v2023.03.01) |
| Nov 15, 2023 | 1.00% (0.00995) | 81.88th | v3 (v2023.03.01) |
| Nov 14, 2023 | 0.62% (0.00624) | 76.54th | v3 (v2023.03.01) |
| Nov 9, 2023 | 0.07% (0.00074) | 30.89th | v3 (v2023.03.01) |
| Nov 3, 2023 | 0.08% (0.00079) | 33.11th | v3 (v2023.03.01) |
References (18)
- https://access.redhat.com/errata/RHSA-2023:6266 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6267 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6268 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6748 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6801 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6803 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6804 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:6810 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2023:7213 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:11049 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2023-46846 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2245910 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/squid-cache/squid/security/advisories/GHSA-j83v-w3p4-5cqh Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00003.html
- https://lists.debian.org/debian-lts-announce/2024/01/msg00008.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-46846
- https://security.netapp.com/advisory/ntap-20231130-0002/
- https://www.cve.org/CVERecord?id=CVE-2023-46846
Change history (0)
No recorded changes yet.